change.php in Ananta CMS 1.0b5, with magic_quotes_gpc disabled, allows remote attackers to gain administrator privileges via a crafted email parameter, possibly related to code injection.
- https://www.exploit-db.com/exploits/5824
No PoCs found on GitHub currently.